The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop, and system crash) via a PRDT with zero complete sectors, related to the bmdma_prepare_buf and ahci_dma_prepare_buf functions.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 30, 2017 | Apr 21, 2015 |
| Debian | — | Upgrade qemu | Jul 30, 2024 | Apr 21, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 31, 2014 |
| Suse | — | Upgrade xenUpgrade xen-doc-pdfUpgrade xen-kmp-defaultUpgrade xen-libsUpgrade qemu-x86Upgrade kvmUpgrade qemu-kvmUpgrade xen-doc-htmlUpgrade qemu-s390Upgrade qemuUpgrade xen-libs-32bitUpgrade xen-tools-domUUpgrade qemu-vgabiosUpgrade qemu-sgabiosUpgrade qemu-ipxeUpgrade qemu-ppcUpgrade qemu-block-rbdUpgrade qemu-toolsUpgrade xen-kmp-paeUpgrade qemu-seabiosUpgrade qemu-guest-agentUpgrade qemu-block-curlUpgrade xen-toolsUpgrade qemu-langUpgrade xen-devel | Mar 28, 2016 | Apr 21, 2015 |
| Ubuntu | — | Upgrade qemu-system-mipsUpgrade qemu-system-ppcUpgrade qemu-system-x86Upgrade qemu-systemUpgrade qemu-system-miscUpgrade qemu-kvmUpgrade qemu-system-sparcUpgrade qemu-system-aarch64Upgrade qemu-system-arm | Nov 8, 2024 | Apr 21, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub